snagrat Posted March 25 Posted March 25 We have an issue where unless we whitelist *.google.com we are unable to login to our Chromebooks using Entra credentials. It will get to the password section then just loop back first saying no network, then returning to the login screen. As whitelisting *.google.com allows it to work it must be a domain that is needed. We have allowed all mentioned by Google Set up a hostname allowlist - Chrome Enterprise and Education Help but still does not work Anyone got an idea what domain is needed?
PaddyNewman Posted March 25 Posted March 25 Are you explicit proxy or transparent? Transparent doesn't like you decrypting www.google.com or accounts.google.com and it will just loop round. You don't need to exclude, but you do need to not decrypt when a user is not logged in (and set the client expiration for something like 3-5 mins refreshing every 2)
snagrat Posted March 25 Author Posted March 25 That is interesting. We are using transparent and are decrypting both those. I will remove them and see what happens tomorrow
PaddyNewman Posted March 25 Posted March 25 Obviously you'll want to decrypt www. Because searches, but for the initial login, if you remove that for a test device and log in, you can decrypt again after. Its finding the way to not decrypt that until you have authenticated. We do it a different way here but its still netsweeper under the hood.
snagrat Posted March 25 Author Posted March 25 Ah interesting you say about decrypting. Both those domains I had as decrypt:// as the URL and Allow. I have removed the rules, but I'm not sure that is what you are referring to.
PaddyNewman Posted March 25 Posted March 25 So you weren't secrypting Google searches by default? There is a big list of dont decrypt these by Google outside of *.google.com one, ill see if I can find it. I know www. and accounts. absolutely hate it on transparent mode.
snagrat Posted March 25 Author Posted March 25 There will be shared lists I don't have access to that might be doing it. When you say do not decrypt it, does it need adding as decrypt://www.google.com (for example) as I always thought that forced it to skip any decryption. If so I will need to add it back in, but then it would need to be removed again once logged in. Only way I can think to do that is to have different VLANs, one for device login and then switch to a different one at user level
PaddyNewman Posted March 25 Posted March 25 (edited) How I would do it is for my IP policies, so the base level, dont decrypt Google with the decrypt://www.google.com or decrypt://google.com to cover the lot, then the policy that your Chromebooks get authenticated against (via the extension assuming you are using that?) You decrypt www.google.com again, so the exemption is only pre authentication. If you aren't using the chromebook agent, this would save you for that. I dont want to tread on many toes as this is likely a competitors Netsweeper, but thats how we manage that side of Chromebooks, agent, no syncing of users, just push chromebooks to the policy of choice via the agent config. This is the list https://support.google.com/chrome/a/answer/6334001?hl=en&ref_topic=3504941#zippy=%2Cenrollment%2Cauto-updates%2Cchromeos-sign-in Googleapis is another domain that we do not decrypt in general, breaks a lot. Oh and the decrypt://google.com is an Allow entry to stop decryption and Denied to enforce it. Edited March 25 by PaddyNewman
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now